F6 XDR MCP Server
OfficialRelated Servers
Alternatives to F6 XDR MCP Server
No user-submitted related servers found.
Related Servers
- AlicenseAqualityFmaintenanceEnables AI assistants to interact with Rapid7 InsightIDR SIEM for investigating incidents, searching logs with LEQL, managing alerts and assets, analyzing user behavior, and handling threat intelligence.264 npm4MIT

UTMStack MCP Serverofficial
AlicenseBqualityAmaintenanceEnables AI assistants to drive the UTMStack SIEM/XDR platform for triaging alerts, searching logs, running SQL, managing incidents, inspecting agents, creating/deleting correlation rules, managing data filters, and running commands on endpoints.44MIT- FlicenseNot gradedqualityDmaintenanceEnables interaction with F5 devices through the iControl REST API to manage objects like virtual servers, pools, iRules, and profiles. It provides comprehensive tools for listing, creating, updating, and deleting F5 configurations via natural language interfaces.-
- AlicenseNot gradedqualityAmaintenanceConnects AI agents with the CrowdStrike Falcon platform to enable intelligent security analysis, providing programmatic access to detections, incidents, threat intelligence, vulnerabilities, and other security capabilities for advanced security operations and automation.258MIT
- AlicenseAqualityCmaintenanceEnables AI agents to interact with IBM QRadar SIEM, including querying and updating offenses, running AQL searches, managing threat intelligence reference sets, and checking console connectivity.27MIT
- AlicenseNot gradedqualityAmaintenanceBrings the full AlertLogic MDR platform into AI assistants, exposing 473+ tools for incident response, log search, SOAR automation, and multi-account security operations at MSSP scale.MIT
TDQS
Scored across 4 tools
Each tool has a clearly distinct purpose: search returns records, count returns aggregates, get_mapping lists searchable fields, and get_filters lists filter options. There is no functional overlap that would cause an agent to select the wrong tool.
All tool names follow a consistent pattern: the xdr_ prefix plus an action verb (search, count, get_mapping, get_filters). The convention is uniform and predictable.
With only 4 tools, the server is tightly scoped to a focused XDR query/exploration workflow. Each tool earns its place, and the count is well within the ideal range.
The server covers the core XDR search workflow well: discover fields, inspect filters, run searches, and get counts. A minor gap is the lack of an explicit tool for listing available XDR sections, but this may be outside the intended scope.